Cyber security remains a growing concern for UK organisations, particularly those operating within healthcare and associated supply chains. Insights from a recent webinar hosted by the Department of Health and Social Care (DHSC) and the National Cyber Security Centre (NCSC) highlight both the scale of current threats and the practical steps organisations can take to protect themselves.
The most significant threat facing UK businesses today is ransomware. However, ransomware attacks are rarely isolated incidents—they are typically enabled by common vulnerabilities and everyday behaviours within organisations.
Three of the most frequent entry points for attackers are:
Other common threats include denial-of-service attacks, spam, and business email compromise.
While threat actors may include state-sponsored groups or independent criminals, the distinction between them is increasingly blurred. Key state actors of concern include Russia, China, Iran, and North Korea. However, for organisations affected by an attack, attribution is often less important—the priority is restoring systems and minimising disruption.
The healthcare sector is a particularly attractive target for cyber attackers due to:
Cyber incidents can have serious operational and financial consequences. In severe cases, attacks can threaten the viability of entire businesses and lead to prolonged recovery periods.
Supply chains are also increasingly targeted. Attackers often focus on smaller organisations within a supply chain, where protections may be weaker. Once compromised, these organisations can act as a gateway to larger, more secure entities. Many supply chain breaches stem from basic weaknesses, particularly phishing attacks.
Managing supply chain risk has become a critical priority. In recent years, many organisations have struggled due to suppliers not fully understanding cyber security risks, a lack of effective tools to evaluate supplier security, and limited visibility across supply chains.
To address this, there is a growing expectation—particularly among larger organisations—that suppliers demonstrate strong cyber security credentials. The Cyber Essentials scheme is now widely recognised as a baseline standard and is increasingly required by the NCSC and the Department for Science, Innovation and Technology (DSIT) across large organisations’ supply chains.
The NCSC’s Cyber Essentials Supply Chain Playbook is a valuable resource that helps organisations assess supplier risk, improve visibility across supply chains, and set appropriate security requirements for partners.
Practical steps organisations can take
Improving cyber security does not need to be complex or costly. The NCSC emphasises that many effective measures are straightforward to implement.
Key actions include:
Preparation is critical to minimising the impact of an attack. Organisations should develop a clear incident response plan, recognising that the first 24 hours of an incident are particularly crucial for an effective response.
This should include ensuring staff understand their roles and responsibilities, planning how to communicate during an incident (especially if systems such as email are unavailable), and regularly testing response plans using tools such as NCSC’s Exercise in a Box.
Testing and refining these plans are essential to ensure they remain effective.
Further guidance and support is available from a range of UK government and cyber security organisations, including the NCSC website, which hosts all tools and guidance, as well as government guidance such as the ministerial letter to large organisations and the ministerial letter to small organisations.
For additional support on supply chain cyber security, organisations can contact: supplychain@iasme.co.uk
Cyber threats continue to evolve, but the steps needed to improve resilience are well understood and accessible. By using the guidance and tools available, BHTA members can significantly reduce their risk and strengthen their overall cyber security posture.
Members are encouraged to review the resources referenced throughout this article and take proactive steps to ensure their organisations are prepared.